Live data from Hacker News

Yahoo Triples Estimate of Breached Accounts to 3B

wsj.com

181–190 of 311 posts

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#181

Earlier quoted context omitted.

Careful there tiger. You're starting to sound like a Sovereign man with your corporate federal account.

I do not know what any of that means. Googling it led to a bunch of conspiracy sites and equally incomprehensible shady semi-legal advice and advocacy sites

late2part was saying that your chain of thought mirrors the conspiracy sites that you mention.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#182
post #160

Earlier quoted context omitted.

That’s a fascinating premise. Revenues generated from the use of ones data is taxed like anything else (unless routed through Ireland ;-) ) but I don’t think assets are taxed at rest. I could be wrong.

Indirectly, they are. Governments don't let you blow all your profits on assets that are as-good-as-cash, and then claim you didn't make any taxable profits. So if you make $X in profit and then use it to buy a tractor, then (from the government's perspective), you've just swapped $X for an asset worth $X. No change in book value, no reduction in profit, no reduction in tax liability. You are, however, allowed to tre…

> Indirectly, they are. Governments don't let you blow all your profits on assets that are as-good-as-cash, and then claim you didn't make any taxable profits.

Similar experience here:

In an earlier career my company reinvested all profits back into growth, only to learn that the taxman didn't care about such silly things. The IRS demanded the tax from the profits that had been reinvested and were no longer available.

Plus they wanted the tax from the profits of the growth that had only happened from reinvesting the earlier profits that they wanted tax from. Their demands were in excess of the actual realized profit that had been made by the company.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#183

Earlier quoted context omitted.

>> User accounts? Really? This is Yahoo we’re talking about. You really do need user accounts to run an email service > Exactly, regardless of that companies keep asking users for a whole collection of personal data, not always making it obvious which fields are actually required You literally don't need any user information to run an email service. You only need a means to identify them which could just amount to gi…

Wouldn't the emails themselves count as user information?

No. User information here means information denoting a user not information from a user.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#184

Earlier quoted context omitted.

> They can, but in practice, they don't. And you're confident of this how? I'm not actually convinced this is true. It's definitely a widespread belief though.

Because I'm using the + thing, and I'm still receiving spam to the +ed addresses.

Weird, I've done that for a long time too and hardly any received spam to those at all. Good to know though, thanks.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#185
post #159

Earlier quoted context omitted.

Sure, but you don't need first name, last name, phone number, birth date or gender. All of which are asked on the signup and of which only Gender is specified as optional: https://login.yahoo.com/account/create On my small business we ask only for an email address, password and confirm password. Everything else is excessive. Tax obligations can be another problem which may require an address, but often have a simpler…

You need to collect date of birth for COPPA compliance

Where in COPPA does it say the DOB needs to be collected? I don't think that statement is true as you word it.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#186
post #142
post #139

Earlier quoted context omitted.

Good point, although the report states 3 billion user accounts were breached but this doesn't mean 3 billion people. I am guessing the vast majority of accounts did not contain any sensitive information. And maybe insurance isn't the right word; the risk should probably fall to the company holding the data, not a third party who would never be able to audit every single step to ensure there is no weak link.

True, it wouldn't be 3 billion individuals claiming the benefit. Still the scale is so large that it would utterly bankrupt most companies to pay out for a single breach.

If the cost of disclosure was a dollar a user there's pretty much no way we'd see them voluntarily tell us they were hacked. We'd have to wait until the information got out some other way.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#187
post #151

Earlier quoted context omitted.

Any non government entity storing data about me (PII and beyond) can only do so with my (revokable) permission and owes me my cut.

In Switzerland, anyone collecting data about other people must make a public declaration of that collection, and may not keep such records about people who disagree with being thus documented ("fiché").

For the curious: There's an English translation of the Federal Act on Data Protection.

https://www.admin.ch/opc/en/classified-compilation/19920153/...

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#188

Earlier quoted context omitted.

User accounts? Really? This is Yahoo we’re talking about. You really do need user accounts to run an email service

Sure, but you don't need first name, last name, phone number, birth date or gender. All of which are asked on the signup and of which only Gender is specified as optional: https://login.yahoo.com/account/create On my small business we ask only for an email address, password and confirm password. Everything else is excessive. Tax obligations can be another problem which may require an address, but often have a simpler…

Tax obligations can be another problem which may require an address, but often have a simpler way to resolve them by simply picking the appropriate country and state off a list or even with just a checkbox for "are you in X jurisdiction which I am required to tax?". I believe Tarsnap handles it that way.

Tarsnap has a "are you Canadian" checkbox. Unfortunately if you are Canadian I have to collect your name and address because I have to provide[0] invoices/receipts which contain this information.

Mind you, there's no requirement that you give me truthful information. If you claim to be John Smith living at 123 Main Street, you'll get an invoice which says that at the top of it. You won't be able to use it to claim a tax rebate; but if you're not running a business it's not useful for that purpose anyway.

[0] IIRC I technically don't have to provide those such invoices to everybody; merely to anyone who asks for one. But collecting the information up front and emailing PDFs to all the Canadians is much easier than handling individual requests later.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#190

3 billion - we live in an age where half the population of the earth can exist on a service, and everyone is vulnerable. Yes, a good chunk of these are probably duplicates for business / spam / anon accounts, but this is where the world is trending. How long is it until facebook or google have a massive breach?

The NSA already breached both Google and Yahoo. I can't remember if they got Facebook too, but it wasn't that big back then.
Post reply on HN